Suno account records
Save account-creation emails, profile screenshots, subscription information, and any security or privacy communications from Suno. Include dates where possible.
Hall Attorneys is evaluating potential claims for Suno users after a reported November 2025 security incident involving 55.3 million email addresses and tens of thousands of Stripe purchase records.
unique email addresses
according to public reports
dataset added to breach index
Answer at a glance
Public reporting describes a November 2025 security incident in which an attacker obtained Suno source code and customer information. Have I Been Pwned later analyzed the reported dataset and listed 55.3 million unique email addresses.
TechCrunch reported that Suno confirmed the incident but had not publicly disclosed it on its website or provided the outlet with a copy of any notice sent to users as of July 21, 2026. The precise information associated with each person may differ.
This is an investigation, not a filed lawsuit. Facts may change as Suno, regulators, or security researchers publish additional information.
A hacker later claimed that a supply-chain attack exposed an employee's credentials and enabled access to Suno systems. TechCrunch reported that Suno described the event as a limited security incident that was quickly contained.
404 Media reported on breached Suno source code, customer information, and Stripe payment data. TechCrunch reported the same day that Suno had not notified customers about the November incident.
Have I Been Pwned added the breach to its index and reported 55.3 million unique email addresses, plus phone numbers and tens of thousands of Stripe purchase records.
TechCrunch reported that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the number of affected users. The outlet said Suno did not provide a copy of any user notification when asked.
Reported data categories
Most of the reported corpus consisted of email addresses. Other information was present only for some users or within a smaller set of Stripe purchase records.
Important distinction
Public sources do not list passwords or full card numbers as compromised data. Partial card details still create phishing and impersonation risks when combined with names, addresses, and purchase information.
Who may want to contact us
The investigation is focused on people whose Suno account, contact, address, purchase, or partial payment-card information may appear in the reported dataset, especially users experiencing misuse or related loss.
Current or former Suno users whose email address appears in the reported dataset
People who used a phone number to create or access a Suno account
Suno customers whose purchases were processed through Stripe
Users receiving targeted phishing, payment-themed messages, or suspicious account communications after the incident
What to preserve
Preserve the records below, but do not send passwords, authentication codes, complete card numbers, or unredacted financial records through ordinary website forms.
Save account-creation emails, profile screenshots, subscription information, and any security or privacy communications from Suno. Include dates where possible.
Preserve Suno receipts, Stripe receipts, subscription changes, refund records, and card alerts. Redact full card numbers before sharing documents by ordinary email.
Keep phishing emails, texts, or direct messages that reference Suno, AI music, subscriptions, billing, refunds, account verification, or personal information.
Save password-reset messages, unfamiliar-login alerts, two-factor authentication prompts, and records of account changes you did not request.
Keep a dated screenshot or PDF if a reputable breach-notification service reports that your email address appears in the Suno dataset.
Track time spent securing accounts, replacing cards, monitoring transactions, responding to phishing, or addressing identity theft or financial loss.
Investigation focus
Hall Attorneys is reviewing the reported attack, the data involved, Suno's response and notice assessment, and follow-on harms reported by users.
Public reporting reviewed
The factual statements above distinguish Suno's reported response from third-party dataset analysis and attacker claims. They may change as more information becomes available.
Have I Been Pwned ·
Lists 55.3 million unique email addresses and the account, purchase, address, and partial payment-card data categories reportedly involved.
Read source: Suno Data Breach404 Media ·
First reported the hack and described access to Suno source code, customer information, and Stripe payment information.
Read source: Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and GeniusTechCrunch ·
Reports the claimed attack path, the customer-data categories, and Suno's description of a limited incident that was quickly contained.
Read source: Hack suggests AI music generator Suno scraped YouTubeTechCrunch ·
Reports that Suno confirmed a November 2025 security incident and did not dispute the number of affected users.
Read source: AI music generator Suno breach affects 55M users, per Have I Been PwnedThe Register ·
Summarizes the dataset size and distinguishes the email-heavy corpus from the smaller set of Stripe purchase records.
Read source: AI music platform Suno hits bum note as 55M users exposed in data breachContact the firm
Contact Hall Attorneys with your name, contact information, general relationship to Suno, and a summary of any notice or suspicious activity. Do not include passwords, authentication codes, complete card numbers, or unredacted financial records in an initial message.
Common questions
No. This page describes an investigation by Hall Attorneys. It does not state that Hall Attorneys has filed a lawsuit over the Suno incident.
TechCrunch reported on July 21, 2026 that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the reported number of affected users. Have I Been Pwned separately lists the incident as the Suno data breach.
Have I Been Pwned lists 55.3 million unique email addresses. That figure describes unique addresses in the dataset; it should not be read as 55.3 million paying customers or as proof that every listed person had every data category exposed.
The reported categories include email addresses, phone numbers used for sign-up, and tens of thousands of Stripe records containing names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of a card. The information associated with a particular person may vary.
Have I Been Pwned does not list passwords among the compromised data categories for this incident. Users should still use a unique password, change any reused password, and enable two-factor authentication where available.
The public reports describe partial card data—not full card numbers—including card type, expiration date, and the last four digits. Have I Been Pwned reports that Suno said it does not have access to customers' full credit card numbers in Stripe.
TechCrunch reported that Suno had not notified customers about the November 2025 incident and, as of July 21, did not provide the outlet with a copy of any user communication when asked. Whether any person received a separate notice remains an issue under investigation.
Use a unique password, enable two-factor authentication where available, monitor the payment card used with Suno, watch for targeted phishing, access Suno through a known official address, and preserve relevant account, purchase, and security records.
Attorney Advertising
Hall Attorneys is not affiliated with Suno, Stripe, or Have I Been Pwned. This page concerns an investigation, not a filed lawsuit. Sending information does not create an attorney-client relationship. Do not send passwords, authentication codes, complete card numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.